CVE-2022-50794
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.
Vendor
Product
CWE
Yayın Tarihi
2025-12-30 23:15:46
Güncelleme
2026-01-13 14:34:19
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-
Kategoriler
Referanslar
https://exchange.xforce.ibmcloud.com/vulnerabilities/247914
https://packetstormsecurity.com/files/170266/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-username-Command-Injection.html
https://www.sound4.com/
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-command-injection-via-username
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5739.php